Description

Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported fields. When a manager or administrator opens the exported CSV file in spreadsheet software, this can cause formula execution and lead to command execution or data exfiltration. This has been patched in version 6.13.0.

INFO

Published Date :

2026-05-05T12:12:49.342Z

Last Modified :

2026-05-05T13:11:01.742Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-27644 vulnerability.

Vendors Products
Traccar
  • Traccar
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact